Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
http://mc.yandex.com/metrika/metrika_match.html

Overview

General Information

Sample URL:http://mc.yandex.com/metrika/metrika_match.html
Analysis ID:1523419
Infos:

Detection

Score:0
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

No high impact signatures.

Classification

  • System is w10x64
  • chrome.exe (PID: 7000 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
    • chrome.exe (PID: 2816 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2196,i,11827700367432253100,18346637809140431528,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • chrome.exe (PID: 1528 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/metrika/metrika_match.html" MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: https://mc.yandex.com/metrika/metrika_match.htmlHTTP Parser: No favicon
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /metrika/metrika_match.html HTTP/1.1Host: mc.yandex.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentsec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /watch/26302566?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461 HTTP/1.1Host: mc.yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mc.yandex.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
Source: global trafficHTTP traffic detected: GET /watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1 HTTP/1.1Host: mc.yandex.ruConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mc.yandex.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: yabs-sid=1664105821727790279; i=Q09KVMtpeVvJriuF1FR5M2RSTwETprkls38TCViqDRXPZzh6l6umLHex99RN9aNIiWxbgrehNVMBJMte4ijJEj0Bptk=; yandexuid=3034093121727790279; yuidss=3034093121727790279; ymex=1759326279.yrts.1727790279#1759326279.yrtsi.1727790279; receive-cookie-deprecation=1; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3Mi
Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: mc.yandex.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-arch: "x86"sec-ch-ua-full-version: "117.0.5938.134"sec-ch-ua-platform-version: "10.0.0"sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"sec-ch-ua-bitness: "64"sec-ch-ua-model: ""sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://mc.yandex.com/metrika/metrika_match.htmlAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: _yasc=pyJkawlffmG5TQ/amYKLyCFw4dTFnzIy+Efj6rD2kdpQcJben7qdSOP9XdFDWsUlzktZ; i=FLD9VYuXpVrF3gLJ9OKsUIM2wlJgaUprC+YmkyhcXsJ/WW5YjTggU3HV2UAy5aopGsN2PookrENc3s60s+jJo0ccR70=; yandexuid=4442907621727790278; yashr=3115653261727790278
Source: global trafficHTTP traffic detected: GET /watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1 HTTP/1.1Host: mc.yandex.ruConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9Cookie: yabs-sid=1664105821727790279; i=Q09KVMtpeVvJriuF1FR5M2RSTwETprkls38TCViqDRXPZzh6l6umLHex99RN9aNIiWxbgrehNVMBJMte4ijJEj0Bptk=; yandexuid=3034093121727790279; yuidss=3034093121727790279; ymex=1759326279.yrts.1727790279#1759326279.yrtsi.1727790279; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3Mi
Source: global trafficHTTP traffic detected: GET /metrika/metrika_match.html HTTP/1.1Host: mc.yandex.comConnection: keep-aliveUpgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Encoding: gzip, deflateAccept-Language: en-US,en;q=0.9
Source: global trafficDNS traffic detected: DNS query: mc.yandex.com
Source: global trafficDNS traffic detected: DNS query: www.google.com
Source: global trafficDNS traffic detected: DNS query: mc.yandex.ru
Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not foundConnection: CloseContent-Length: 0Date: Tue, 01 Oct 2024 13:44:43 GMTStrict-Transport-Security: max-age=31536000X-XSS-Protection: 1; mode=block
Source: chromecache_42.2.drString found in binary or memory: https://mc.kinopoisk.ru/sync_cookie_image_check
Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49711 version: TLS 1.2
Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49713 version: TLS 1.2
Source: classification engineClassification label: clean0.win@17/2@10/5
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2196,i,11827700367432253100,18346637809140431528,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
Source: unknownProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/metrika/metrika_match.html"
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2196,i,11827700367432253100,18346637809140431528,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8Jump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknownJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath Interception1
Process Injection
1
Process Injection
OS Credential DumpingSystem Service DiscoveryRemote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media3
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive4
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture3
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
mc.yandex.ru
93.158.134.119
truefalse
    unknown
    bg.microsoft.map.fastly.net
    199.232.214.172
    truefalse
      unknown
      www.google.com
      216.58.206.36
      truefalse
        unknown
        default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
        217.20.57.43
        truefalse
          unknown
          mc.yandex.com
          unknown
          unknownfalse
            unknown
            NameMaliciousAntivirus DetectionReputation
            https://mc.yandex.com/metrika/metrika_match.htmlfalse
              unknown
              https://mc.yandex.ru/watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1false
                unknown
                https://mc.yandex.ru/watch/26302566?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461false
                  unknown
                  https://mc.yandex.com/favicon.icofalse
                    unknown
                    http://mc.yandex.com/metrika/metrika_match.htmlfalse
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://mc.kinopoisk.ru/sync_cookie_image_checkchromecache_42.2.drfalse
                        unknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        239.255.255.250
                        unknownReserved
                        unknownunknownfalse
                        93.158.134.119
                        mc.yandex.ruRussian Federation
                        13238YANDEXRUfalse
                        87.250.251.119
                        unknownRussian Federation
                        13238YANDEXRUfalse
                        216.58.206.36
                        www.google.comUnited States
                        15169GOOGLEUSfalse
                        IP
                        192.168.2.7
                        Joe Sandbox version:41.0.0 Charoite
                        Analysis ID:1523419
                        Start date and time:2024-10-01 15:43:39 +02:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 3m 7s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:browseurl.jbs
                        Sample URL:http://mc.yandex.com/metrika/metrika_match.html
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:15
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Detection:CLEAN
                        Classification:clean0.win@17/2@10/5
                        EGA Information:Failed
                        HCA Information:
                        • Successful, ratio: 100%
                        • Number of executed functions: 0
                        • Number of non-executed functions: 0
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                        • Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.250.184.206, 74.125.71.84, 34.104.35.123, 52.165.165.26, 199.232.214.172, 20.242.39.171, 40.69.42.241, 13.95.31.18, 142.250.186.163, 88.221.110.91, 2.16.100.168
                        • Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, clientservices.googleapis.com, ctldl.windowsupdate.com, time.windows.com, a767.dspw65.akamai.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, fe3.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, update.googleapis.com, clients.l.google.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size getting too big, too many NtSetInformationFile calls found.
                        • VT rate limit hit for: http://mc.yandex.com/metrika/metrika_match.html
                        No simulations
                        No context
                        No context
                        No context
                        No context
                        No context
                        Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                        File Type:HTML document, ASCII text, with very long lines (525)
                        Category:downloaded
                        Size (bytes):2660
                        Entropy (8bit):5.4924201070051515
                        Encrypted:false
                        SSDEEP:48:pfEh80BxIAIlIDeSVcekFPfJrkkPn58ox4McXQeoQ7ZICgrsvMYj:MIAIlI/cegJvi37zV
                        MD5:BE4BB752EDB4886CA34EC2FDA51B517F
                        SHA1:A14ED5B28119253F347D946E00541E26CAFEF559
                        SHA-256:4A5CECD1D4605282ACE7A74EA526E1EEEF35FE54E6B1A0415A34485D6CFEBE70
                        SHA-512:978885E00DA21ADE36D1313C5A1C3DCAA62967BC220F785D5A6CF078EDFA71C1CB695689343580C9801A28052A96EB56C9FE6054F2042B2AA47245B0B0F9D33E
                        Malicious:false
                        Reputation:low
                        URL:https://mc.yandex.com/metrika/metrika_match.html
                        Preview:<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">.<html>.<head>. <meta http-equiv="X-UA-Compatible" content="IE=edge">. <meta http-equiv="Content-Type" content="text/html;charset=UTF-8">.</head>.<body>.<script>(function(){try{(function(){function k(a){var c=a.document;if(c.hasStorageAccess)c.hasStorageAccess().then(function(b){a.parent.postMessage("sc.sar*"+(b?"1":"2"),"*")})["catch"](function(){a.parent.postMessage("sc.sar*c","*")})}function h(a){try{return encodeURIComponent(a)}catch(c){}a=t("",u(function(c){return 55296>=c.charCodeAt(0)},a.split("")));return encodeURIComponent(a)}function t(a,c){return Array.prototype.join.call(c,a)}function u(a,c){return Array.prototype.filter.call(c,a)}function v(a){function c(b,.e){var l="sc.topics-response*"+b;a.parent.postMessage(e?l+"*"+e:l,"*")}a.document.browsingTopics().then(function(b){return c("1",JSON.stringify(b))})["catch"](function(){return c("e")})}function f(a,c,b){void 0===b&&(b=!0);re
                        No static file info
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 1, 2024 15:44:26.083771944 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:26.395937920 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:27.005326986 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:27.989737034 CEST49674443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:27.992403984 CEST49675443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:28.036643028 CEST49672443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:28.208478928 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:30.614703894 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:34.691278934 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:35.162113905 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:35.474842072 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:36.052648067 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:36.656229973 CEST4970480192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:36.656344891 CEST4970580192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:36.660980940 CEST804970493.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:36.661098003 CEST804970593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:36.661149025 CEST4970480192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:36.661169052 CEST4970580192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:36.661365986 CEST4970480192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:36.666121006 CEST804970493.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:37.373264074 CEST804970493.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:37.385495901 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:37.385557890 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:37.385636091 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:37.385924101 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:37.385940075 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:37.414052010 CEST4970480192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:37.554137945 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:37.601221085 CEST49674443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:37.601244926 CEST49675443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:37.649028063 CEST49672443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:37.916877031 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:37.916925907 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:37.917006969 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:37.917541027 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:37.917556047 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.106076956 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.106331110 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.106360912 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.107418060 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.107491970 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.109718084 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.109778881 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.110199928 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.110208035 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.151899099 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.471419096 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.471493959 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.471540928 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.471564054 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.471601009 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.487613916 CEST49708443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.487637997 CEST4434970887.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.553035975 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.576872110 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:38.576919079 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.578007936 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.578078032 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:38.598608971 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:38.598716974 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.615036964 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.615128040 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.615202904 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.617889881 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:38.617934942 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:38.646495104 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:38.646533966 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:38.691092014 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:39.339154005 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.340434074 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.340497971 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.341655970 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.341722965 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.606372118 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.606545925 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.607320070 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.607342005 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.661163092 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.784754038 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:39.784807920 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:39.784945965 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:39.789304972 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:39.789315939 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:39.839035988 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.839143038 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:39.839140892 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:39.839201927 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:40.111126900 CEST44349698104.98.116.138192.168.2.7
                        Oct 1, 2024 15:44:40.112406015 CEST49698443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:40.304722071 CEST49710443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:40.304766893 CEST4434971087.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:40.346632004 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:40.346684933 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:40.346743107 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:40.347536087 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:40.347563982 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:40.451343060 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.451416969 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.462110043 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.462130070 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.462553024 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.505429029 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.536216974 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:40.710513115 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.751439095 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.897198915 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.897330999 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.897401094 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.901788950 CEST49711443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.901809931 CEST44349711184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.958964109 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.959017038 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:40.959086895 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.959408045 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:40.959419966 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:41.070945024 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.071341038 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.071377993 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.071741104 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.072151899 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.072231054 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.072356939 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.115402937 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.442186117 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.442274094 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.442341089 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.575161934 CEST49712443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.575192928 CEST4434971287.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.593046904 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.593091965 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:41.593174934 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.593955040 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:41.593964100 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:42.585839987 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.585994005 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.597481012 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.597501993 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.597829103 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.616250992 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:42.616295099 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:42.618341923 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:42.619653940 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:42.619663000 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:42.645513058 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.657824039 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.699420929 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.867420912 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.867510080 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.867661953 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.868531942 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.868550062 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:42.868586063 CEST49713443192.168.2.7184.28.90.27
                        Oct 1, 2024 15:44:42.868592024 CEST44349713184.28.90.27192.168.2.7
                        Oct 1, 2024 15:44:43.302242994 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:43.324945927 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:43.324959040 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:43.325356007 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:43.326904058 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:43.326961994 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:43.327361107 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:43.367408037 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:44.387765884 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.388017893 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:44.388056040 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.388073921 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:44.388083935 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.388112068 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:44.388622999 CEST49714443192.168.2.787.250.251.119
                        Oct 1, 2024 15:44:44.388639927 CEST4434971487.250.251.119192.168.2.7
                        Oct 1, 2024 15:44:44.389069080 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.389125109 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.390353918 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.390417099 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.390837908 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.390851021 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.442930937 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.987914085 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.988009930 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:44.988066912 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.989217997 CEST49715443192.168.2.793.158.134.119
                        Oct 1, 2024 15:44:44.989238977 CEST4434971593.158.134.119192.168.2.7
                        Oct 1, 2024 15:44:45.083573103 CEST49671443192.168.2.7204.79.197.203
                        Oct 1, 2024 15:44:46.489847898 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:44:48.466171026 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:48.466253042 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:48.466306925 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:48.647217989 CEST49698443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:48.648969889 CEST49717443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:48.649027109 CEST44349717104.98.116.138192.168.2.7
                        Oct 1, 2024 15:44:48.649091959 CEST49717443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:48.652159929 CEST44349698104.98.116.138192.168.2.7
                        Oct 1, 2024 15:44:48.658503056 CEST49717443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:44:48.658513069 CEST44349717104.98.116.138192.168.2.7
                        Oct 1, 2024 15:44:49.322057009 CEST49709443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:44:49.322079897 CEST44349709216.58.206.36192.168.2.7
                        Oct 1, 2024 15:44:58.396401882 CEST49677443192.168.2.720.50.201.200
                        Oct 1, 2024 15:45:21.662206888 CEST4970580192.168.2.793.158.134.119
                        Oct 1, 2024 15:45:21.668394089 CEST804970593.158.134.119192.168.2.7
                        Oct 1, 2024 15:45:22.380995035 CEST4970480192.168.2.793.158.134.119
                        Oct 1, 2024 15:45:22.385926008 CEST804970493.158.134.119192.168.2.7
                        Oct 1, 2024 15:45:31.419524908 CEST44349717104.98.116.138192.168.2.7
                        Oct 1, 2024 15:45:31.419627905 CEST49717443192.168.2.7104.98.116.138
                        Oct 1, 2024 15:45:38.247936964 CEST4970580192.168.2.793.158.134.119
                        Oct 1, 2024 15:45:38.248698950 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:38.248738050 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:38.249536037 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:38.250477076 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:38.250488997 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:38.254081011 CEST804970593.158.134.119192.168.2.7
                        Oct 1, 2024 15:45:38.254142046 CEST4970580192.168.2.793.158.134.119
                        Oct 1, 2024 15:45:38.929894924 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:38.945696115 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:38.945719957 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:38.946074963 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:38.953375101 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:38.953449011 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:39.005980968 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:48.923101902 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:48.923158884 CEST44349723216.58.206.36192.168.2.7
                        Oct 1, 2024 15:45:48.923333883 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:49.324769020 CEST49723443192.168.2.7216.58.206.36
                        Oct 1, 2024 15:45:49.324804068 CEST44349723216.58.206.36192.168.2.7
                        TimestampSource PortDest PortSource IPDest IP
                        Oct 1, 2024 15:44:34.593594074 CEST53528271.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:34.594682932 CEST53515331.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:35.653748035 CEST53579051.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:36.641926050 CEST5767753192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:36.642364979 CEST5062753192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:36.649482965 CEST53576771.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:36.649725914 CEST53506271.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:37.377491951 CEST5377353192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:37.377861023 CEST6077153192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:37.384208918 CEST53537731.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:37.384965897 CEST53607711.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:37.904112101 CEST5591953192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:37.904480934 CEST5608853192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:37.910824060 CEST53559191.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:37.911854029 CEST53560881.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:38.605854988 CEST5255553192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:38.606496096 CEST6430053192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:38.613094091 CEST53525551.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:38.613343954 CEST53643001.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:40.900778055 CEST123123192.168.2.713.95.65.251
                        Oct 1, 2024 15:44:41.082855940 CEST12312313.95.65.251192.168.2.7
                        Oct 1, 2024 15:44:41.602860928 CEST6015053192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:41.604166985 CEST6152653192.168.2.71.1.1.1
                        Oct 1, 2024 15:44:42.587975979 CEST53601501.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:42.588083029 CEST53615261.1.1.1192.168.2.7
                        Oct 1, 2024 15:44:52.789551020 CEST53493811.1.1.1192.168.2.7
                        Oct 1, 2024 15:45:11.394108057 CEST53588141.1.1.1192.168.2.7
                        Oct 1, 2024 15:45:33.731848955 CEST53651581.1.1.1192.168.2.7
                        Oct 1, 2024 15:45:34.203489065 CEST53547091.1.1.1192.168.2.7
                        Oct 1, 2024 15:45:35.121098995 CEST138138192.168.2.7192.168.2.255
                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                        Oct 1, 2024 15:44:36.641926050 CEST192.168.2.71.1.1.10x4efdStandard query (0)mc.yandex.comA (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:36.642364979 CEST192.168.2.71.1.1.10xaf55Standard query (0)mc.yandex.com65IN (0x0001)false
                        Oct 1, 2024 15:44:37.377491951 CEST192.168.2.71.1.1.10x75e4Standard query (0)mc.yandex.comA (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.377861023 CEST192.168.2.71.1.1.10x1b5dStandard query (0)mc.yandex.com65IN (0x0001)false
                        Oct 1, 2024 15:44:37.904112101 CEST192.168.2.71.1.1.10xa55eStandard query (0)www.google.comA (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.904480934 CEST192.168.2.71.1.1.10x901eStandard query (0)www.google.com65IN (0x0001)false
                        Oct 1, 2024 15:44:38.605854988 CEST192.168.2.71.1.1.10xe3e1Standard query (0)mc.yandex.ruA (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:38.606496096 CEST192.168.2.71.1.1.10xf3cfStandard query (0)mc.yandex.ru65IN (0x0001)false
                        Oct 1, 2024 15:44:41.602860928 CEST192.168.2.71.1.1.10xa761Standard query (0)mc.yandex.ruA (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:41.604166985 CEST192.168.2.71.1.1.10x7339Standard query (0)mc.yandex.ru65IN (0x0001)false
                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                        Oct 1, 2024 15:44:36.649482965 CEST1.1.1.1192.168.2.70x4efdNo error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                        Oct 1, 2024 15:44:36.649482965 CEST1.1.1.1192.168.2.70x4efdNo error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:36.649482965 CEST1.1.1.1192.168.2.70x4efdNo error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:36.649482965 CEST1.1.1.1192.168.2.70x4efdNo error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:36.649482965 CEST1.1.1.1192.168.2.70x4efdNo error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:36.649725914 CEST1.1.1.1192.168.2.70xaf55No error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384208918 CEST1.1.1.1192.168.2.70x75e4No error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384208918 CEST1.1.1.1192.168.2.70x75e4No error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384208918 CEST1.1.1.1192.168.2.70x75e4No error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384208918 CEST1.1.1.1192.168.2.70x75e4No error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384208918 CEST1.1.1.1192.168.2.70x75e4No error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.384965897 CEST1.1.1.1192.168.2.70x1b5dNo error (0)mc.yandex.commc.yandex.ruCNAME (Canonical name)IN (0x0001)false
                        Oct 1, 2024 15:44:37.910824060 CEST1.1.1.1192.168.2.70xa55eNo error (0)www.google.com216.58.206.36A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:37.911854029 CEST1.1.1.1192.168.2.70x901eNo error (0)www.google.com65IN (0x0001)false
                        Oct 1, 2024 15:44:38.613094091 CEST1.1.1.1192.168.2.70xe3e1No error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:38.613094091 CEST1.1.1.1192.168.2.70xe3e1No error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:38.613094091 CEST1.1.1.1192.168.2.70xe3e1No error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:38.613094091 CEST1.1.1.1192.168.2.70xe3e1No error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:42.587975979 CEST1.1.1.1192.168.2.70xa761No error (0)mc.yandex.ru93.158.134.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:42.587975979 CEST1.1.1.1192.168.2.70xa761No error (0)mc.yandex.ru77.88.21.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:42.587975979 CEST1.1.1.1192.168.2.70xa761No error (0)mc.yandex.ru87.250.251.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:42.587975979 CEST1.1.1.1192.168.2.70xa761No error (0)mc.yandex.ru87.250.250.119A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:49.229374886 CEST1.1.1.1192.168.2.70xe153No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:44:49.229374886 CEST1.1.1.1192.168.2.70xe153No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:03.827449083 CEST1.1.1.1192.168.2.70xdf40No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:03.827449083 CEST1.1.1.1192.168.2.70xdf40No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comdefault.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comCNAME (Canonical name)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.43A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.20A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.21A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.21A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com84.201.210.36A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.37A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.40A (IP address)IN (0x0001)false
                        Oct 1, 2024 15:45:26.467017889 CEST1.1.1.1192.168.2.70x86d6No error (0)default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.57.19A (IP address)IN (0x0001)false
                        • mc.yandex.com
                        • https:
                          • mc.yandex.ru
                        • fs.microsoft.com
                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.74970493.158.134.119802816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        Oct 1, 2024 15:44:36.661365986 CEST454OUTGET /metrika/metrika_match.html HTTP/1.1
                        Host: mc.yandex.com
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Accept-Encoding: gzip, deflate
                        Accept-Language: en-US,en;q=0.9
                        Oct 1, 2024 15:44:37.373264074 CEST113INHTTP/1.1 302 Moved temporarily
                        Content-Length: 0
                        Location: https://mc.yandex.com/metrika/metrika_match.html
                        Oct 1, 2024 15:45:22.380995035 CEST6OUTData Raw: 00
                        Data Ascii:


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.74970593.158.134.119802816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        Oct 1, 2024 15:45:21.662206888 CEST6OUTData Raw: 00
                        Data Ascii:


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        0192.168.2.74970887.250.251.1194432816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:38 UTC682OUTGET /metrika/metrika_match.html HTTP/1.1
                        Host: mc.yandex.com
                        Connection: keep-alive
                        Upgrade-Insecure-Requests: 1
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: navigate
                        Sec-Fetch-User: ?1
                        Sec-Fetch-Dest: document
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        sec-ch-ua-platform: "Windows"
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-01 13:44:38 UTC1315INHTTP/1.1 200 OK
                        Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                        Accept-Ranges: bytes
                        Access-Control-Allow-Origin: *
                        Cache-Control: max-age=3600
                        Connection: Close
                        Content-Length: 2660
                        Content-Type: text/html
                        Date: Tue, 01 Oct 2024 13:44:38 GMT
                        ETag: "66fb0aa6-a64"
                        Expires: Tue, 01 Oct 2024 14:44:38 GMT
                        Last-Modified: Mon, 30 Sep 2024 20:31:34 GMT
                        Set-Cookie: _yasc=pyJkawlffmG5TQ/amYKLyCFw4dTFnzIy+Efj6rD2kdpQcJben7qdSOP9XdFDWsUlzktZ; domain=.yandex.com; path=/; expires=Fri, 29 Sep 2034 13:44:38 GMT; secure
                        Set-Cookie: i=FLD9VYuXpVrF3gLJ9OKsUIM2wlJgaUprC+YmkyhcXsJ/WW5YjTggU3HV2UAy5aopGsN2PookrENc3s60s+jJo0ccR70=; Expires=Thu, 01-Oct-2026 13:44:38 GMT; Domain=.yandex.com; Path=/; Secure; HttpOnly; SameSite=None
                        Set-Cookie: yandexuid=4442907621727790278; Expires=Thu, 01-Oct-2026 13:44:38 GMT; Domain=.yandex.com; Path=/; Secure; SameSite=None
                        Set-Cookie: yashr=3115653261727790278; Path=/; Domain=.yandex.com; Expires=Wed, 01 Oct 2025 13:44:38 GMT; SameSite=None; Secure; HttpOnly
                        Strict-Transport-Security: max-age=31536000
                        Timing-Allow-Origin: *
                        2024-10-01 13:44:38 UTC2660INData Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 57 33 43 2f 2f 44 54 44 20 48 54 4d 4c 20 34 2e 30 31 2f 2f 45 4e 22 20 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 54 52 2f 68 74 6d 6c 34 2f 73 74 72 69 63 74 2e 64 74 64 22 3e 0a 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 58 2d 55 41 2d 43 6f 6d 70 61 74 69 62 6c 65 22 20 63 6f 6e 74 65 6e 74 3d 22 49 45 3d 65 64 67 65 22 3e 0a 20 20 20 20 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 63 68 61 72 73 65 74 3d 55 54 46 2d 38 22 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 73 63 72 69 70
                        Data Ascii: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd"><html><head> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <meta http-equiv="Content-Type" content="text/html;charset=UTF-8"></head><body><scrip


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        1192.168.2.74971087.250.251.1194432816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:39 UTC691OUTGET /watch/26302566?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461 HTTP/1.1
                        Host: mc.yandex.ru
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Sec-Fetch-Site: cross-site
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://mc.yandex.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        2024-10-01 13:44:39 UTC1881INHTTP/1.1 302 Moved temporarily
                        Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                        Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
                        Connection: Close
                        Date: Tue, 01 Oct 2024 13:44:39 GMT
                        Expires: Tue, 01-Oct-2024 13:44:39 GMT
                        Last-Modified: Tue, 01-Oct-2024 13:44:39 GMT
                        Location: /watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1
                        Pragma: no-cache
                        Set-Cookie: yabs-sid=1664105821727790279; Path=/; SameSite=None; Secure
                        Set-Cookie: i=Q09KVMtpeVvJriuF1FR5M2RSTwETprkls38TCViqDRXPZzh6l6umLHex99RN9aNIiWxbgrehNVMBJMte4ijJEj0Bptk=; Expires=Fri, 29-Sep-2034 13:44:35 GMT; Domain=.yandex.ru; Path=/; Secure; HttpOnly; SameSite=None
                        Set-Cookie: yandexuid=3034093121727790279; Expires=Fri, 29-Sep-2034 13:44:35 GMT; Domain=.yandex.ru; Path=/; Secure; SameSite=None
                        Set-Cookie: yuidss=3034093121727790279; Expires=Wed, 01-Oct-2025 13:44:39 GMT; Domain=.yandex.ru; Path=/; SameSite=None; Secure
                        Set-Cookie: ymex=1759326279.yrts.1727790279#1759326279.yrtsi.1727790279; Expires=Wed, 01-Oct-2025 13:44:39 GMT; Domain=.yandex.ru; Path=/; SameSite=None; Secure
                        Set-Cookie: receive-cookie-deprecation=1; Expires=Wed, 01-Oct-2025 13:44:39 GMT; Domain=.yandex.ru; Path=/; SameSite=None; Secure; HttpOnly; Partitioned
                        Set-Cookie: bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3Mi; Expires=Wed, 01-Oct-2025 13:44:39 GMT; Domain=.yandex.ru; Path=/; SameSite=None; Secure
                        Strict-Transport-Security: max-age=31536000
                        Transfer-Encoding: chunked
                        X-XSS-Protection: 1; mode=block
                        2024-10-01 13:44:39 UTC5INData Raw: 30 0d 0a 0d 0a
                        Data Ascii: 0


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        2192.168.2.749711184.28.90.27443
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:40 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-10-01 13:44:40 UTC467INHTTP/1.1 200 OK
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (lpl/EF06)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-neu-z1
                        Cache-Control: public, max-age=183670
                        Date: Tue, 01 Oct 2024 13:44:40 GMT
                        Connection: close
                        X-CID: 2


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        3192.168.2.74971287.250.251.1194432816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:41 UTC1101OUTGET /watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1 HTTP/1.1
                        Host: mc.yandex.ru
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Sec-Fetch-Site: cross-site
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://mc.yandex.com/
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: yabs-sid=1664105821727790279; i=Q09KVMtpeVvJriuF1FR5M2RSTwETprkls38TCViqDRXPZzh6l6umLHex99RN9aNIiWxbgrehNVMBJMte4ijJEj0Bptk=; yandexuid=3034093121727790279; yuidss=3034093121727790279; ymex=1759326279.yrts.1727790279#1759326279.yrtsi.1727790279; receive-cookie-deprecation=1; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3Mi
                        2024-10-01 13:44:41 UTC664INHTTP/1.1 200 Ok
                        Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                        Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
                        Connection: Close
                        Content-Length: 43
                        Content-Type: image/gif
                        Date: Tue, 01 Oct 2024 13:44:41 GMT
                        Expires: Tue, 01-Oct-2024 13:44:41 GMT
                        Last-Modified: Tue, 01-Oct-2024 13:44:41 GMT
                        Pragma: no-cache
                        Strict-Transport-Security: max-age=31536000
                        X-XSS-Protection: 1; mode=block
                        2024-10-01 13:44:41 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                        Data Ascii: GIF89a!,D;


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        4192.168.2.749713184.28.90.27443
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:42 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                        Connection: Keep-Alive
                        Accept: */*
                        Accept-Encoding: identity
                        If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                        Range: bytes=0-2147483646
                        User-Agent: Microsoft BITS/7.8
                        Host: fs.microsoft.com
                        2024-10-01 13:44:42 UTC515INHTTP/1.1 200 OK
                        ApiVersion: Distribute 1.1
                        Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                        Content-Type: application/octet-stream
                        ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                        Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                        Server: ECAcc (lpl/EF06)
                        X-CID: 11
                        X-Ms-ApiVersion: Distribute 1.2
                        X-Ms-Region: prod-weu-z1
                        Cache-Control: public, max-age=183612
                        Date: Tue, 01 Oct 2024 13:44:42 GMT
                        Content-Length: 55
                        Connection: close
                        X-CID: 2
                        2024-10-01 13:44:42 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                        Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        5192.168.2.74971487.250.251.1194432816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:43 UTC1118OUTGET /favicon.ico HTTP/1.1
                        Host: mc.yandex.com
                        Connection: keep-alive
                        sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                        sec-ch-ua-mobile: ?0
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        sec-ch-ua-arch: "x86"
                        sec-ch-ua-full-version: "117.0.5938.134"
                        sec-ch-ua-platform-version: "10.0.0"
                        sec-ch-ua-full-version-list: "Google Chrome";v="117.0.5938.134", "Not;A=Brand";v="8.0.0.0", "Chromium";v="117.0.5938.134"
                        sec-ch-ua-bitness: "64"
                        sec-ch-ua-model: ""
                        sec-ch-ua-platform: "Windows"
                        Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                        Sec-Fetch-Site: same-origin
                        Sec-Fetch-Mode: no-cors
                        Sec-Fetch-Dest: image
                        Referer: https://mc.yandex.com/metrika/metrika_match.html
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: _yasc=pyJkawlffmG5TQ/amYKLyCFw4dTFnzIy+Efj6rD2kdpQcJben7qdSOP9XdFDWsUlzktZ; i=FLD9VYuXpVrF3gLJ9OKsUIM2wlJgaUprC+YmkyhcXsJ/WW5YjTggU3HV2UAy5aopGsN2PookrENc3s60s+jJo0ccR70=; yandexuid=4442907621727790278; yashr=3115653261727790278
                        2024-10-01 13:44:44 UTC179INHTTP/1.1 404 Not found
                        Connection: Close
                        Content-Length: 0
                        Date: Tue, 01 Oct 2024 13:44:43 GMT
                        Strict-Transport-Security: max-age=31536000
                        X-XSS-Protection: 1; mode=block


                        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                        6192.168.2.74971593.158.134.1194432816C:\Program Files\Google\Chrome\Application\chrome.exe
                        TimestampBytes transferredDirectionData
                        2024-10-01 13:44:44 UTC838OUTGET /watch/26302566/1?page-url=https%3A%2F%2Fmc.yandex.com%2Fmetrika%2Fmetrika_match.html&browser-info=ar%3A1%3Apv%3A1%3Av%3A1461&redirnss=1 HTTP/1.1
                        Host: mc.yandex.ru
                        Connection: keep-alive
                        User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                        Accept: */*
                        Sec-Fetch-Site: none
                        Sec-Fetch-Mode: cors
                        Sec-Fetch-Dest: empty
                        Accept-Encoding: gzip, deflate, br
                        Accept-Language: en-US,en;q=0.9
                        Cookie: yabs-sid=1664105821727790279; i=Q09KVMtpeVvJriuF1FR5M2RSTwETprkls38TCViqDRXPZzh6l6umLHex99RN9aNIiWxbgrehNVMBJMte4ijJEj0Bptk=; yandexuid=3034093121727790279; yuidss=3034093121727790279; ymex=1759326279.yrts.1727790279#1759326279.yrtsi.1727790279; bh=EkAiR29vZ2xlIENocm9tZSI7dj0iMTE3IiwgIk5vdDtBPUJyYW5kIjt2PSI4IiwgIkNocm9taXVtIjt2PSIxMTciKgI/MDoJIldpbmRvd3Mi
                        2024-10-01 13:44:44 UTC664INHTTP/1.1 200 Ok
                        Accept-CH: Sec-CH-UA-Bitness, Sec-CH-UA-Arch, Sec-CH-UA-Full-Version, Sec-CH-UA-Mobile, Sec-CH-UA-Model, Sec-CH-UA-Platform-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform, Sec-CH-UA, UA-Bitness, UA-Arch, UA-Full-Version, UA-Mobile, UA-Model, UA-Platform-Version, UA-Platform, UA
                        Cache-Control: private, no-cache, no-store, must-revalidate, max-age=0
                        Connection: Close
                        Content-Length: 43
                        Content-Type: image/gif
                        Date: Tue, 01 Oct 2024 13:44:44 GMT
                        Expires: Tue, 01-Oct-2024 13:44:44 GMT
                        Last-Modified: Tue, 01-Oct-2024 13:44:44 GMT
                        Pragma: no-cache
                        Strict-Transport-Security: max-age=31536000
                        X-XSS-Protection: 1; mode=block
                        2024-10-01 13:44:44 UTC43INData Raw: 47 49 46 38 39 61 01 00 01 00 80 00 00 00 00 00 00 00 00 21 f9 04 01 00 00 00 00 2c 00 00 00 00 01 00 01 00 00 02 02 44 01 00 3b
                        Data Ascii: GIF89a!,D;


                        Click to jump to process

                        Click to jump to process

                        Click to jump to process

                        Target ID:0
                        Start time:09:44:29
                        Start date:01/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized "about:blank"
                        Imagebase:0x7ff6c4390000
                        File size:3'242'272 bytes
                        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:2
                        Start time:09:44:32
                        Start date:01/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2300 --field-trial-handle=2196,i,11827700367432253100,18346637809140431528,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                        Imagebase:0x7ff6c4390000
                        File size:3'242'272 bytes
                        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:false

                        Target ID:9
                        Start time:09:44:35
                        Start date:01/10/2024
                        Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                        Wow64 process (32bit):false
                        Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" "http://mc.yandex.com/metrika/metrika_match.html"
                        Imagebase:0x7ff6c4390000
                        File size:3'242'272 bytes
                        MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:low
                        Has exited:true

                        No disassembly